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(54) Trace cache for a nfticroprocessor-based device 



(57) A processor-based device (1 02) incorporating 
an on-chip instruction trace cache (200) capable of pro- 
viding infomiatlon for reconstructing instruction execu- 
tion fiow. The trace infomiation can be captured without 
halting normal processor (104) operation. Both serial 
(204) and parallel (214) communication channels are 
provided for communbating the trace infonmation to ex- 
ternal devices. In the disclosed embodiment of the in- 
vention, instmctions that disrupt the instruction flow are 
reported, particularly instructions in which the target ad- 
dress Is In some way data dependent For example, call 



instructions or unconditional branch instructions in 
which tiie target address is provided from a data register 
(or other memory location such as a stack) cause a trace 
cache entry to be generated. In the case of many un- 
conditional branches or sequential instructions, no entry 
is placed into the trace cache (200) because the target 
address can be completely detemnined from the Instruc- 
tion stream. Other Infomnation provided by the Instruc- 
tion trace cache (200) includes: the target address of a 
trap or Intenrupt handler, the target address of a return 
Instruction, addresses from procedure returns, task 
identifiers, and trace capture stop/start infonnatlon. 
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Description 
TECHNICAL FIELD 

[0001] The invention relates to software debug support In microprocessors, and more particularly to a microproces- 
sor-based device Incorporating an on-chip Instruction trace cache. 

BACKGROUND ART 

[0002] The growth In software complexity, coupled with Increasing processor clock speeds, has placed an increasing 
burden on application software developers. The cost of developing and debugging new software products is now a 
significant factor In processor selection. A processor's failure to adequately facilitate software debug results In longer 
customer development times and reduces the processor's attractiveness for use within Industry. The need to provide 
software debug support is particularly acute within the embedded products Industry, where specialized on-chip circuitry 
is often combined with a processor core. 

[0003] In addition to the software engineer, other parties are also affected by debug tool configuration. These parties 
include: the "trace" algorithm developer who must search through captured software trace data that reflects instruction 
execution flow in a processor; the In-circuit emulator developer who deals with problems of signal synchronization, 
clock frequency and trace bandwidth; and the processor manufacturer who does not want a solution that results in 
increased processor cost or design and development complexity. 

[0004] With desktop systems, complex multitasking operating systems are currently available to support debugging. 
However, the initial task of getting these operating systems running reliably often requires special development equip- 
ment. While not the standard In the desktop environment, the use of such equipment is often the approach taken within 
the embedded industry. Logic analyzers, read-only memory (ROM) emulators and In-clrcuit emulators (ICE) are fre- 
quently employed. In-circult emulators do provide certain advantages over other debug environments, offering complete 
control and visibility over memory and register contents, as well as overlay and trace memory in case system memory 
is InsufficienL Use of traditional in-circuit emulators, which Involves Interfacing a custom emulator back-end with a 
processor socket to allow communication between emulation equipment and the target system, is becoming Increas- 
ingly difficult and expensive In today's age of exotic packages and shrinking product life cycles, 
[0005] Assuming full-function in-circult emulation is required, there are a few known processor manufacturing tech- 
niques able to offer the required support for emulation equipment. Most processors Intended for personal computer 
(PC) systems utilize a multiplexed approach In which existing pins are multiplexed for use In software debug. This 
approach is not particularly desirable in the embedded industry, where it is more difficult to overioad pin functionality. 
[0006] Other more advanced processors multiplex debug pins In time. In such processors, the address bus is used 
to report software trace information during a BTA-cycle (Branch Target Address). The BTA-cycle, however, must be 
stolen from the regular bus operation. In debug environments where branch activity is high and cache hit rates are low, 
It becomes impossible to hide the BTA-cycles. The resulting conflict over access to the address bus necessitates 
processor "throttle back" to prevent loss of instruction trace infonnation. In the communications indust^, for example, 
software typically makes extensive use of branching and suffers poor cache utilization, often resulting in 20% throttle 
back or more. This amount of throttling is unacceptable amount for embedded products which must accommodate 
real-time constrains. 

[0007] In another approach, a second "trace" or "slave" processor Is combined with the main processor, with the two 
processors operating in-step. Only the main processor Is required to fetch Instructions. The second, slave processor 
Is used to monitor the fetched instructions on the data bus and keeps its intemal state in synchronization with the main 
processor. The address bus of the slave processor functions to provide trace Information. After power-up, via a JTAG 
(Joint Test Action Group) input, the second processor is switched into a slave mode of operation. Free from the need 
to fetch Instmctions, Its address bus and other pins provide the necessary trace Information. 
[0008] Another existing approach Involves building debug support into every processor, but only bonding-out the 
necessary signal pins in a limited number of packages. These "specially" packaged versions of the processor are used 
during debug and replaced with the smaller package for final production. This bond-out approach suffers from the need 
to support additional bond pad sites in all fabricated devices. This can be a burden In small packages and pad limited 
designs, particularty if a substantial number of "extra" pins are required by the debug support variant. Additionally, the 
debug capability ofthe specially packaged processors Is unavailable in typical processor-based production systems. 
[0009] in yet another approach (the "Background Debug Mode" by Motorola, Inc.) limited on-chip debug clrcultiy is 
provided for basic run control. Through a dedicated serial link requiring additional pins, this approach allows a debugger 
to start and stop the target system and apply basic code breakpoints by inserting special instaictlons in system memory. 
Once halted, special commands are used to inspect memory variables and register contents. This serial link, however,, 
does not provide trace support - additional dedicated pins and expensive external trace capture hardware are required 
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to provide instruction trace data. European patent application EP-A-O 762 276 of Motorola describes a debug module 
of a data processor which provides a parallel output portfor providing internal operating Information via a DDATA signal 
and a PSTsignal. The DDATA signal provides data which reflects operand values and the PSTsignal provides encoded 
status Information which reflects an execution status of the central processing unit. 

[0010J Thus, the current solutions for software debugging suffer from a variety of limitations. Including: increased - 
packaging and development costs, circuit complexity, processorthrottling, and bandwidth matching difficulties Further 

therelscun-entlynoadequatelow-costprocedureforprovidlngtracelnfomiatlon.Thelimltatlonsoftheexistlngsd 
are likely to be exacerbated In the future as intemal processor clock frequencies continue to increase. 

DISCLOSURE OF THE INVENTION 

[00111 Briefly, a processor-based device according to the present invention includes an on^hlp Instruction trace 
cache capable of providing information for reconstructing Instruction execution flow The trace Information can be cap- 
tured without halting normal processor operation. Both serial and parallel communication channels are provided for 
communicating the trace infomiatlon to external devices. In the disclosed embodiment of the Invention, controllability 
and observability of the instruction trace cache are achieved through a software debug port that uses an IEEE- 1 
149.1-1990 compliant JTAG (Joint Test Action Group) Interface or a similar standardized Interface that Is integrated 
Into the processor-based device. 

[001 2] According to a first aspect, the present invention provides an electronic processor-based device adapted to 
execute a series of instructions obtained from external sources, the processor-based device being provided with pins 
to permit connection to external conductors, the electronic processor-based device being characterized by: 

a trace cache coupled to a processor core for storing trace information Indicative of the order In which the instruc- 
tions are executed by the processor core, the trace cache comprising a series of storage elements, each storage 
element being adapted to store trace information, the trace information Including a plurality of instruction trace 
records containing address and data Information, the trace cache being configured to load data from the processor 
core in response to a load command and configured for the processor core to retrieve data from the trace cache 
in response to a retrieve command; 

and a communication Interface connected between the trace cache and selected ones of the pins to provide for 
transmission of trace information from the trace cache to external devices. 

[0013] According to a second aspect the present Invention provides method for analysing trace Information In a 
processor-based device having a processor core comprising the steps of: 

providing a trace cache within the processor-based device the trace cache comprising a series of storage elemente 
adapted to store trace infonnation; 

capturing trace infomiatlon from the processor core that is lndlcatlve of the order in whteh the series of instructions 
is executed by the processor core; 

storing the trace infonnation in the trace cache storage elements as instruction trace records; 

retrieving the trace Information by the processor core from the trace cache storage elements In response to a 

retrieve command; and 

loading other information from the processor core Into the trace cache storage elements In response to a load 
command; 

providing a communication channel from the trace cache to selected pins of the processor-based device and 
communicating the trace Information from the trace cache to the selected pins via th9 communication channel. 

[0014] Preferably, infonnation stored In the instruction trace cache Is "compressed" such that a smaller cache can 
be utilized. In addition, compressing trace data allows external hardware to operate at normal bus speeds, even while 
the intemal processor is operating much faster. Less expensive external capture hardware can therefore be utilized 
with a processor-based device according to the invention. 

[0015] In the disclosed embodiment of the Invention, if an address in an instruction stream can be obtained from a 
program image (Object Module), then It is not provided In the trace data. Preferably, only instructions that disrupt the 
instruction flow are reported; and further, only instructions in which the target address is In some way data dependent 
Such disrupting" events include, for example, call instructions or unconditional branch instructions In which the target 
address is provided from a data register or other memory location such as a stack. In the case of many unconditional 
branches or sequential Instructions, no entry is placed into the trace cache because the target address can be com- 
pletely determined from tiie Instruction stream. Other Information provided by the instruction trace cache includes- the 
target address of a trap or intemipt handler, the target address of a return instruction, addresses from procedure returns 
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task identifiers, and trace capture stop/start Information. This technique reduces the amount of information transfen-ed 
from the trace cache to external debug hardware. 

[0016] Thus, a processor-based device supplying a flexible, high-perfomiance solution forf urnlshlng instruction trace 
Information is provided by the Invention. The disclosed on-chip instruction trace cache alleviates various of the band- 
width and clocic synchronization problems that arise in many existing solutions. 

BRIEF DESCRIPTION OF DRAWINGS 



[0017] A better understanding of the present Invention can be obtained when the following detailed description of 
the preferred embodiment is considered in conjunction with the following drawings, In which: 

Figure 1 is a block diagram of a software debug environment utilizing a software debug solution In accordance 
with the present invention; 

Figure 2 is a block diagram providing details of an exemplary embedded processor product Incorporating an on- 
chip-instmctlorr trace cache according to the present Invention; 

Figure 3 is a simplified block diagram depicting the relationship between an exemplary Instruction trace cache and 
other components of an embedded processor product according to the present invention; 
Figure 4 Is a flowchart illustrating software debug command passing according to one embodiment of the Invention; 
Figure 5 is a flowchart illustrating enhanced software port command passing according to a second embodiment 
of the invention; and 

Figures 6A - 6G illustrate the general fomiat of a variety of trace cache entries for reporting Instruction execution 
according to the invention. 



MODE{S) FOR CARRYING OUT THE INVENTION 



[0018] Tuming now to the drawings, Figure 1 depicts an exemplary software debug environment Illustrating a con- 
templated use of the present invention. A target system T is shown containing an embedded processor device 102 
according to the present invention coupled to system memory 1 06. The embedded processor device 1 02 Incorporates 
a processor core 1 04, an Instruction trace cache 200 (Figure 2). and a debug port 1 00. Although not considered critical 
to the Invention, the embedded processor device 102 may incorporate additional circuitry (not shown) for performing 
application specific functions, or may take the form of a stand-alone processor or digital signal processor. Preferably, 
the debug port 100 uses an IEEE-1149.M 990 compliant JTAG Interface or other similar standarxlized serial port in- 
terface. 

[0019] A host system H Is used to execute debug control software 112 for transferring high-level commands and 
controlling the extraction and analysis of debug infonnation generated by the target system T The host system H and 
target system T of the disclosed embodiment of the invention communicate via a serial link 110. Most computers are 
equipped with a serial or parallel Interface which can be inexpensively connected to the debug port 100 by means of 
a serial connector 1 08, allowing a variety of computers to function as a host system H. Alternatively, the serial connector 
1 08 could be replaced with higher speed JTAG-to-networi? conversion equipment. Further, the target system T can be 
configured to analyze debug/trace Infomnatlon Internally. 

[0020] Referring now to Figure 2, details of an embedded processor device 1 02 according to the present invention 
are provided, in addition to the processor core 104, Figure 2 depicts various elements of an enhanced embodiment of 
the debug port 100 capable of utilizing and controlling the trace cache 200. Many other configurations are possible, 
as will become apparent to those skilled in the art, and the various processor device 1 02 components described below 
are shown for purposes of illustrating the benefits associated with providing an on-chip trace cache 200. 
[0021 ] Of significance to the disclosed embodiment of the invention, the trace control circuitry 21 8 and trace cache 
200 operate to provide trace Information for reconstnjcting instruction execution flow In the processor core 104. The 
trace control circuitry 21 8 supports "tracing" to a trace pad Interface port 220 or to the Instruction trace cache 200 and 
provides user control for selectively activating Instruction trace capture. Other features enabled by the trace control 
circuitry 218 include programmabiirty of synchronization address generation and user specified trace recorxJs, as dls- 
cussed In greater detail below. The trace control circuitry 21 8 also controls a trace pad interface port 220. When utilized, 
the trace pad Interface port 220 Is capable of providing trace data while the processor core 1 04 is executing instructions! 
although clock synchronization and other Issues may arise. The Instruction trace cache 200 addresses many of these 
issues, Improving bandwidth matching and alleviating the need to Incorporate throttle-back circuitry In the processor 
core 104. 

[0022] At a minimum, only the conventional JTAG pins need be supported In the software debug port 100 in the 
described embodiment of the invention. The JTAG pins essentially become a transportation mechanism, using existing 
pins, to enter commands to be perfonned by the processor core 1 04. More specifically, the test clock signal TCK. the 
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test mode select signal TMS, the test data Input signal TDI and the test data output signal TDO provided to and driven 
by the JTAG Test Access Port (TAP) controller 204 are conventional JTAG support signals and known to those skilled 
In the art. As discussed In more detail below, an "enhanced" embodiment of the debug port 100 adds the command 
acknowledge signal CMDACK, the break requestArace capture signal BRTC, the stop transmit signal STOPTX and 
the trigger signal TRIG to the standard JTAG interface. The addrtlonal signals allow for pinpoint accuracy of external 
breakpoint assertion and monitoring, triggering of external devices in response to internal breakpoints, and elimination 
of status polling of the JTAG serial interface. These "sideband" signals offer extra functionality and improve commu- 
nications speeds for the debug port 1 00. These signals also aid in the operation of an optional parallel port 21 4 provided 
on special bond-out versions of the disclosed embedded processor device 102. 

[0023] Via the conventional JTAG signals, the JTAG TAP controller 204 accepts standard JTAG serial data and 
control. When a DEBUG Instruction has been written to the JTAG instruction register, a serial debug shifter 212 Is 
connected to the JTAG test data Input signal TDI and test data output signal TDO, such that commands and data can 
then be loaded into and read from debug registers 210. In the disclosed embodiment of the invention, the debug 
registers210 include two debug registers for transmitting (TX_DATA register) and receiving (RX.DATA register) data 
an Instruction trace-configuration register (ITCR), and a debug control status register (DCSR). 
[0024] A control interface state machine 206 coordinates the loading/reading of data to/from the serial debug shifter 
212 and the debug registers 210. A command decode and processing block 208 decodes commands/data and dis- 
patches them to processor Interface logic 202 and trace debug Interface logto 216. In addition to performing other 
functions, the trace debug Interface logic 21 6 and trace control logic 21 8 coordinate the communication of trace infor- 
mation from the trace cache 200 to the TAP controller 204. The processor interface logte 202 communteates directly 
with the processor core 104, as well as the trace control logic 218. As described more fully below, parallel port logic 
214 communicates with a control interface state machine 206 and the debug registers 210 to perfomi parallel data 
read/write operations In optional bond-out versions of the embedded processor device 102. 
[0025] Before debug Infomiation is communicated via the debug port 1 00 using only conventional JTAG signals the 
port 1 00 IS enabled by writing the public JTAG instruction DEBUG into a JTAG instruction register contained within the 
TAP controller 204. As shown below, the JTAG Instruction register of the disclosed embodiment is a 38-bit register 
compnstng a 32-blt data field (debug_data[31 :0]), a four4)it command field to point to various Internal registers and 
functions provided by the debug port 100, a command pending flag, and a command finished flag. It is possible for 
some commands to use bits from the debug_data field as a sub-field to extend the number of available commands 
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[0026] This JTAG Instruction register is selected by toggling the test mode select signal TMS. The test mode select 
signal TMS allows the JTAG path of clocking to be changed In the scan path , enabling m ultipie paths of varying lengths 
to be used. Preferably, the JTAG instruction register Is accessible via a short path. This register is configured to include 
a soft" register for holding values to be loaded Into or received from specified system registers. 
[0027] Refening now to Figure 3, a simplified block diagram depicting the relationship between an exemplary In- 
struction trace cache 200 and other components of an embedded processor device 102 according to the present 
invention Is shown. In one contemplated embodiment of the Invention, the trace cache 200 is a 128 entry first-ln first- 
out (FIFO) circular cache that records the most recent trace entries, increasing the size of the trace cache 200 increases 
the amount of instruction trace infonmatlon that can be captured, although the amount of required silicon area may 
increase. 

[0028] As described in more detail below, the trace cache 200 of the disclosed embodiment of the invention stores 
a plurality of 20-bit (or more) trace entries Indicative of the order in which instructions are executed by the processor 
core 104. Other infonnatlon, such as task identifiers and trace capture stop/start information, can also be placed in the 
trace cache 200. The contents of the trace cache 200 are provided to external hardware, such as the host system H 
V a either serial or parallel trace pins 230. Alternatively, the target system T can be configured to examine the content^ 
of the trace cache 200 internally 

[0029] Figure 4 provides a high-level flow chart of command passing when using a standard JTAG interface Upon 
entenng debug mode in step 400 the DEBUG Instruction Is written to the TAP controller 204 in step 402 Next step 
404, the 38-bit serial value is shifted in as a whole, with the command pending flag set and desired data (if applltiable 
othenvlse zero) In the data field. Control proceeds to step 406 where the pending command is loaded/unloaded and 
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the command finished flag checked. Completion of a command typically involves transferring a value between a data 
register and a processor register or memoiy/IO location. After the command has been completed, the processor 1 04 
clears the command pending flag and sets the command finished flag, at the same time storing a value in the data 
field If applicable. The entire 38-blt register Is scanned to monitor the command finished and command pending flags 
If the pending flag Is reset to zero and the finished flag is set to one, the previous command has finished. The status 
of the flags is captured by the control interface state machine 206. A slave copy of the flags' status is saved internally 
to detemiine If the next Instruction should be loaded. The slave copy Is maintained due to the possibility of a change 
in flag status between TAP controller 204 states. Th is allows the processor 1 04 to determine if the previous Instruction 
has finished before loading the next instmction. 

[0030] '[theflnlshedflagisnotsetasdetemilnedlnstep408.controlproceedstostep410andtheloading/unload^ 
of the se-bit command is repeated. The command finished flag Is also checked. Control then returns to step 408 If 
LL '® ^ detemilned In step 408, control returns to step 408 for processing of the next command. 

DEBUG mode is exited via a typical JTAG process. 

[0031] Returning to Figure 2, the aforementioned optional sideband signals are utilized in the enhanced debug port 
100 to provWe extra functionality. The optional sideband signals include a break requestArace capture signal BRTC 
that can function as a break request signal or a trace capture enable signal depending on the status of bit set In the 
debug control/status register. If the break requestArace capture signal BRTC Is set to function as a break request 
signal, It Is asserted to cause the processor 104 to enter debug mode (the processor 104 can also be stopped by 
scanning in a halt command via the convention JTAG signals). If set to function as a trace capture enable signal 
asseitingthebreakrequesVtracecaptureslgnai BRTCenables trace capture. Deasserting 
off. The signal takes effect on the next instruction boundary after ft is detected and is synchronized with the Internal 
processor clock. The break request/trace capture signal BFTTC may be asserted at any time. 
[0032] The trigger signal TRIG is configured to pulse whenever an internal processor breakpoint has been asserted 
The tngger signal TRIG may be used to trigger an external capturing device such as a logic analyzer, and is synchro- 
nized with the trace record capture clock signal TRACECLK. When a breakpoint is generated, the event is synchronized 
with the trace capture clock signal TRACECLK, after which the trigger signal TRIG Is held active for the duration of 
trace capture. 

[0033] The stop transmit signal STOPTX is asserted when the processor 104 has entered DEBUG mode and Is 
ready for register interrogation/modification, memory or I/O reads and writes through the debug port 100 in the dis- 
closed embodiment of the Invention, the stop transmit signal STOPTX reflects the state of a bit In the debug control 
status register (DCSR). The stop transmit signal STOPTX is synchronous with the trace capture clock signal TRACE- 
CLK. 

[0034] The command acknowledge signal CMDACK is described in conjunction with Figure 5, which shows simplified 
command passing in the enhanced debug port 1 00 of Figure 2. Again, to place the target system T into DEBUG mode 
a DEBUG instruction is written to the TAP controller 204 in step 502. Control proceeds to step 504 and the command 
acknowledge signal CMDACK is monitored by the host system H to determine command completion status. This signal 
is asserted high by the target system T simultaneously with the command finished flag and remains high until the next 
shift cycle begins. When using the command acknowledge signal CMDACK, It is not necessary to shift out the JTAG 
instruction register to capture the command finished flag status. The command acknowledge signal CMDACK transl- 
tions high on the next rising edge of the test clock signal TCK after the command finished flag has changed from zero 
to one. When using the enhanced JTAG signals, a new shift sequence (step 506) is not started by the host system H 
until the command acknowledge signal CMDACK pin has been asserted high. The command acknowledge signal 
CMDACK Is synchronous with the test clock signal TCK. The test clock signal TCK need not be clocked at ail times 
but IS Ideally clocked continuously when waiting for a command acknowledge signal CMDACK response. 

OPERATING SYSTEM/APPLICATION COMMUNICATION VIA THE DEBUG POFTT 100 

[0035] Also Included in debug register block 210 Is an Instruction trace configuration register (ITCR) This 32-bit 
register provides for the enabllng/disabling and configuration of Instruction trace debug functions. Numerous such 
functions are contemplated, including various levels of tracing, trace synchronization force counts, trace Initialization 
instruction tracing modes, clock divider ratio information, as well as additional functions shown in the following table' 
TTie ITCR Is accessed through a JTAG instruction register write/read command as is the case with the other registers 
of the debug register block 21 0, or via a reserved Instruction. 
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Instruction Trace Configuration Register (iTCR). 




BIT 


SYI\4B0L 


DESCRIPTION/FUNCTION 


5 


31:30 


Reserved 


Resen/ed 




29 


RXINTEN 


Enables interrupt when RX bit is set 




28 


TXINTEN 


Enables interrupt when TX bit is set 


10 


27 


TX 


indicates that the target system T Is ready to transmit data to the host system H and the 
data is available In the TX^DATA register 




£0 


RX 


Indicates that data has been received from the host and placed in the RX_DATA register 




oc 
20 


DISLITR 


Disables level 1 tracing 


15 


24 


DISLOTR 


Disables levelO tracing. 




CO 


DISCSB 


Disables current segment base trace record 






TSYNC[6:0] 


Sets the maximum number of Branch Sequence trace records that may be output by the 
trace control biocic 21 8 before a synchronizing address record is forced 


20 


15 


1 ono 


Sets or clears trace mode on DBS trap 




14 


TSR2 


Sets or clears trace mode on DR2 trap 




13 


TSR1 


Sets or clears trace mode on DR1 trap 


25 


io 
r<: 


TSRO 


Sets or clears trace mode on DRO trap 




11 


TRACES 


Enables Trace mode toggling using DR3 




< f\ 
lO 


TRACE2 


Enables Trace mode toggling using DR2 




9 


TRACE1 


Enables Trace mode toggling using DR1 


30 


8 


TRACEO 


Enables Trace mode toggling using DRO 




7 


TRON 


Trace on/off 




6:4 


TCLK[2:01 


Encoded dwider ratio between Internal processor ciocl< and TRACECLK 


35 


3 


ITM 


Sets Internal or external (bond-out) instruction tracing mode 




2 


TINIT 


Trace Initialization 




1 


TRIGEN 


Enables pulsing of external trigger signal TRIG following receipt of any legacy debug 
breakpoint; independent of the Debug Trap Enable function in the DCSR 


40 


0 


GTEN 


Global enable for instruction tracing through the intemai trace buffer or via the external 
(bond-out) interface 



45 



SO 



[00361 Another debug register, the debug control/status register (DCSR), provides an Indication of when the proc- 

e^r 04 has entered debug mode and allows the processor104 to be forced IntoDEBUG mode through the enhanced 
JTAG Interface. As shown in the following table, the DCSR also enables miscellaneous control features such as' 
forcing a ready signal to the processor 1 04, controlling memoiy access space for accesses Initiated through the debug 
port, disabling cache flush on entiy to the DEBUG mode, the TX and RX bits, the parallel port 214 enable, forced 
breate forced global reset, and other functions. The ordering or presence of the various bits In either the ITCR or 
DCSR is not considered critical to the operation of the Invention. 





Debug Control/Status Register (DCSR). 


BIT 


SYiVIBOL 


DESCRIPTION/FUNCTION 


31:12 


Resen/ed 


Reserved 


11 


TX 


indicates that the target system T is ready to transmit data to the host system H and the 
data is available in the TX_DATA register 
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(continued) 





Debug Control/Status Register (DCSR). 


BIT 


SYMBOL 


DESCRIPTION/FUNCTION 


10 


RX 


Indicates that data has been received from the host and placed In the RX.DATA register 


9 


DISFLUSH 


Disables cache flush on entry to DEBUG mode 


8 


SMMSP 


Controls memory access space (normal memorv soace/ svstem manAnAmAnt mnHa 
memory) for accesses initiated through the Debug Port 100 


7 


STOP 


Indicates whether the processor 1 04 Is In DEBUG mode (equivalent to stop transmit signal 
STOPTX 


6 


FRCRDY 


Forces the ready signal RDY to the processor 1 04 to be pulsed for one processor clock; 
useful when It is apparent that the processor 1 04 |s stalled waiting for a ready signal from 
a non-responding device 


5 


BRKMODE 


Selects the function of the break requestArace capture signal BRTC (break request ortrace 
capture on/off) 


4 


DBTEN 


Enables entry to debug mode or toggle trace mode enable on a trap/fault via processor 104 
registers DR0-DR7 or other legacy debug trap/fault mechanisms 


3 


PARENS 


Enables parallel port 214 


2 


DSPC 


Disables stopping of Internal processor clocks In the Halt and Stop Grant states 


1 


FBRK 


Forces processor 104 Into DEBUG mode at the next instruction boundary (equivalent to 
pulsing the extemal BRTC pin) 


0 


PRESET 


Forces global reset 



10 
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[0037J When In cross debug environment such as that of Figure 1 . it Is necessary for the parent task running on the 
target system T to send information to the host platform H controlling it. This data may consist, for example of a 
character stream from a prlntf() call or register infom^ation from a Task's Control Block (TCB). One contemplated 
method for transferring the data Is forthe operating system to place the data in a known region, then via a trap Instruction 
cause DEBUG mode to be entered. ' 
[0038] Via debug port 1 00 commands, the host system H can then detemiine the reason that DEBUG mode was 
entered, and respond by retrieving the data from the reserved region. However, while the processor 1 04 is in DEBUG 
mode, normal processor execution Is stopped. As noted above, this Is undesirable for many reai-time systems. 
[0039] This situation is addressed according to the present invention by providing two debug registers in the debug 
port 100 fortransmltting (TX.DATA register) and receiving (RX^DATA register) data. These registers can be accessed 
using the soft address and JTAG instruction register commands. As noted, after the host system H has written a debug 
instruction to the JTAG instruction register, the serial debug shifter 21 2 is coupled to the test data input siqnal TDI line 
and test data output signal TDO line. 

[0040] When the processor 1 04 executes code causing It to transmit data, it first tests a TX bit in the ITCR. If the TX 
bit IS set to zero then the processor 1 04 executes a processor Instruction (either a memory or I/O write) to transfer the 
data to the TX.DATA register. The debug port 100 sets the TX bit in the DCSR and ITCR, Indicating to the host system 
H that It is ready to transmit data. Also, the STOPTX pin Is set high. After the host system H completes reading the 
transmit data from the TX.DATA register, the TX bit Is set to zero. A TXINTEN bit In the ITCR Is then set to generate 
a signal to interrupt the processor 1 04. The Interrupt is generated only when the TX bit in the ITCR transitions to zero 
When the TXINTEN bit Is not set. the processor 104 polls the ITCR to determine the status of the TX bit to further 
transmit data. 

[0041] When the host system H desires to send data, it first tests a RX bit in the ITCR. If the RX bit Is set to zero 
the host system H writes the data to the RX_DATA register and the RX bit Is set to one In both the DCSR and ITCr' 
A RXIhrr bit is then set in the ITCR to generate a signal to interrupt the processor 1 04. This Inten-upt is on^ generated 
when the RX in the ITCR transitions to one. When the RXINTEN bit Is not set. the processor 104 polls the ITCR to 
verify the status of the RX bit. If the RX bit Is set to one, the processor instruction Is executed to read data from the 
RX.DATA register. After the data Is read by the processor 104 from the RX.DATA register the RX bit is set to zero 
The host system H continuously reads the ITCR to detemiine the status of the RX bit to further send data. 
[0042] This technique enables an operating system or application to communicate with the host system H without 
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stopping processor 1 04 execution . Communication is conveniently ach ieved via the debug port 1 00 with minimal Impact 
to on-chip application resources. In some cases It is necessary to disable system Interrupts. This requires that the RX 
and TX bits be examined by the processor 100. In this situation, the communication link is driven in a polled mode. 

PARALLEL INTERFACE TO DEBUG PORT 1 00 

[0043] Some embedded systems require instruction trace to be examined while maintaining I/O and data processing 
operations. Without the use of a multi-tasking operating system, a bond-out version of the embedded processor device 
102 Is preferable to provide the trace data, as examining the trace cache 20O via the debug port 100 requires the 
processor 104 to be stopped. 

[0044] In the disclosed embodiment of the Invention, a parallel port 214 Is also provided in an optional bond-out 
version of the embedded processor device 102 to provide parallel command and data access to the debug port 100. 
This interface provides a 16-bit data path that Is multiplexed with the trace pad Interface port 220. More specifically, 
the parallel port 214 provides a 16-bit wide bi-directional data bus (PDATA[15:0]), a 3-bit address bus (PADR[2:0]), a 
parallel debug port read/write select stgnal (PRWy, a trace valid signal TV and an Instnfctlon trace record output ctock 
TRACECLOCK (TC). Although not shared with the trace pad interface port 220, a parallel bus request/grant signal pair 
PBREQ/PBGNT (not shown) are also provided. The parallel port 214 Is enabled by setting a bit in the DCSR. Serial 
communications via the debug port 100 are not disabled when the parallel port 214 is enabled. 



22 21 20 


19 


16 




0 


TV 


TC 


PRW 


PADR [2:0] 


PD ATA [15:0] 



Bond-Out Pins/Parallel Port 2 14 Format 

[0045] The parallel port 21 4 Is primarily intended for fast downloads/uploads to and from target system T memory. 
However, the parallel port 214 may be used for all debug communteatlons with the target system T whenever the 
processor 1 04 is stopped. The serial debug signals (standard or enhanced) are used for debug access to the target 
system T when the processor 1 04 is executing instructions. 

[0046] In a similar manner to the JTAG standard, ail Inputs to the parallel port 214 are sampled on the rising edge 
of the test clock signal TCK, and all outputs are changed on the falling edge of the test clock signal TCK. In the disclosed 
embodiment, the parallel port 214 shares pins with the trace pad interface 220, requiring parallel commands to be 
initiated only while the processor 1 04 is stopped and the trace pad Interface 220 is disconnected from the shared bus. 
[0047] The parallel bus request signal PBREQ and parallel bus grant signal PBGNT are provided to expedite multi- 
plexing of the shared bus signals between the trace cache 200 and the parallel port 214. When the host Interface to 
the parallel port 214 detemiines that the parallel bus request signal PBREQ Is asserted, It begins driving the parallel 
port 214 signals and asserts the parallel bus grant signal PBGNT 

[0048] When entering or leaving DEBUG mode with the parallel port 214 enabled, the parallel port 214 is used for 
the processor state save and restore cycles. The parallel bus request signal PBREQ is asserted immediately before 
the beginning of a save state sequence penultimate to entry of DEBUG mode. On the last restore state cycle, the 
parallel bus request signal PBREQ is deasserted after latching the write data. The parallel port 214 host interface 
responds to parallel bus request signal PBREQ deassertion by tri-stating Its parallel port drivers and deasserting the 
parallel bus grant signal PBGNT The parallel port 214 then enables the debug trace port pin drivers, completes the 
last restore state cycle, asserts the command acknowledge signal CMDACK, and returns control of the interface to 
trace control logk:218. 

[0049] When communicating via the parallel port 21 4, the address pins PADR[2:0] are used for selection of the field 
of the JTAG instruction register, which is mapped to the 16-bit data bus PDATA[15:6] as shown in the following table: 



PADR[2:0] 


Data Selection 


000 


No selection (null operation) 


001 


4-bit command register; command driven on PDATA[3:0] 


010 


High 1 6-bits of debug_data 


011 


Low 16-bits of debugudata 
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(continued) 



5 



PADR[2:01 


Data Selection 


100-111 


Reserved 



[0050] It Is not necessary to update both iialves of the debucudata [31 :01 register if only one of the halves is being 
used (e.g., on 8-blt I/O cycle data writes). The command pending flag is automatically set when performing a write 
operation to the four-bit command register, and is cleared when the command finished flag is asserted. The host system 
io H can monitor the command acknowledge signal CMDACK to detennine when the finished flag has been asserted. 
Use of the parallel port 21 4 provides full visibility of execution history, without requiring throttling of the processor core 
104. The trace cache 200, if needed, can be configured for use as a buffer to the parallel port 214 to alleviate any 
bandwidth matching Issues. 

IS OPERATING SYSTERA^AND DEBUGGER INTEGRATION 

[0051] In the disclosed embodiment of the invention, the operation of all debug supporting features, including the 
trace cache 200, can be controlled through the debug port 1 00 or via processor instnjctions. These processor instruc- 
tions may be from a monitor program, target hosted debugger, or conventional pod-wear. The debug port 100 performs 
20 data moves which are Initiated by serial data port commands rather than processor Instructions. 

[0052] Operation of the processor from conventional pod-space Is very similar to operating In DEBUG mode from a 
monitor program. All debug operations can be controlled via processor Instructions. It makes no difference whether 
these Instructions come from pod-space or regular memory. This enables an operating system to be extended to include 
additional debug capabilities. 

25 [00531 Of course, via privileged system calls such a ptraceQ, operating systems have long supported debuggers. 

However, the incorporation of an on-chip trace cache 200 now enables an operating system to offer instruction trace 

capability. The ability to trace is often considered essential in real-time applications. In a debug environment according 

to the present invention, it is possible to enhance an operating system to support limited trace without the incorporation 

of an "external" logic analyzer or In-clrcuit emulator. 
30 [0054] Examples of instructions used to support intemal loading and retrieving of trace cache 200 contents include 

a load instruction trace cache reconJ command LITCR and a store instruction trace cache record command SiTGR. 

The command LITCR loads an indexed record In the trace cache 200, as specified by a trace cache pointer ITREC. 

PTR, with the contents of the EAX register of the processor core 104. The trace cache pointer ITREC.PTR is pre- 

incremented, such that the general operation of the command LITCR is as follows: 

35 

ITREC.PTR <- ITREC.PTR +1; 

iTREc/m?Ec.prf?;<- eax. 

In the event that the instruction trace record (see description of trace record fonnat below) is smaller that the EAX 
4Q record, only a portion of the EAX register is utilized. 

[0055] Similarly, the store instruction trace cache record command SITCR is used to retrieve and store (in the EAX 
register) an indexed record from the trace cache 200. The contents of the ECX register of the processor core 1 04 are 
used as an offset that is added to the trace cache pointer ITREC.PTR to create an index Into the trace cache 200. The 
ECX register Is post-Incremented while the trace cache pointer ITREC.PTR is unaffected, such that: 

45 

EAX <- ITREC^£CX+ fTREC.PfRl 
ECX<-ECX + 1. 

Numerous variations to the format of the LITCR and SITCR commands will be evident to those skilled art. 

so [0056] Extending an operating system to support on-chip trace has certain advantages within the communications 
Industry, it enables the system I/O and communication activity to be maintained while a task is being traced. Tradition- 
ally, the use of an in-circuit emulator has necessitated that the processor be stopped before the processor's state and 
trace can be examined [unlike ptraceQ]. This disaipts continuous support of I/O data processing. 
[0057] Additionally, the trace cache200 is very useful when used with equipment in the field, if an unexpected system 

55 crash occurs, the trace cache 200 can be examined to observe the execution history leading up to the crash event 
When used in portable systems or other environments In which power consumption is a concem, the trace cache 200 
can be disabled as necessary via power management cln:ultry. 
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EXEMPLARY TRACE RECORD FORMAT 

[0058J In the disclosed embodiment of the Invention, an Instnjction trace record is 20 bits wide and consists of two 
fields, TCODE (Trace Code) and TDATA (Trace Data), as well as a valid bit V. The TCODE field is a code that Identifies 
the type of data In the TDATA field. The TDATA field contains software trace information used for debug purposes. 
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TCODE (Trace Code) 



TDATA (Trace Data) 



Instruction Trace Record Format. 
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[0059] In one contemplated embodiment of the invention, the embedded processor device 102 reports eleven dif- 
ferent trace codes as set forth in the following table: 



TGODE# 


TCODE Type 


TDATA 


0000 


Missed Trace 


Not Valid 


0001 


Conditional Branch 


Contains Branch Sequence 


0010 


Branch Target 


Contains Branch Target Address 


0011 


Previous Segment Base 


Contains Previous Segment Base Address and Attributes 


0100 


Current Segment Base 


Contains Current Segment Base Address and Attributes 


0101 


interrupt 


Contains Vector Number of Exception or Interrupt 


0110 


Trace Synchronization 


Contains Address of Most Recently Executed Instruction 


0111 


Multiple Trace 


Contains 2nd or 3rd Record of Entry With Multiple Records 


1000 


Trace Stop 


Contains Instruction Address Where Trace Capture Was Stopped 


1001 


User Trace 


Contains User Specified Trace Data 


1010 


Performance Profile 


Contains Performance Profiling Data . 



[0060] The trace cache 200 is of limited storage capacity; thus a certain amount of "compression" in captured trace 
data is desirable. In capturing trace data, the following discussion assumes that an image of the program being traced 
is available to the host system H. If an address can be obtained from a program image (Object Module), then It is not 
provided In the trace data. Preferably, only instructions which disrupt the Instruction flow are reported; and further, only 
those where the target address is in some way data dependent. For example, such "disrupting" events Include call 
instructions or unconditional branch Instmctions in which the target address is provided from a data register or other 
memory location such as a stack. 

[0061] As Indicated In the preceding table, other desired trace infomiation Includes; the target address of a trap or 
interrupt handler; the target address of a return instruction; a conditional branch instmction having a target address 
which is data register dependent (othenwise, all that is needed is a 1 -bit trace indicating if the branch was taken or not); 
and, most frequently, addresses from procedure returns. Other infomiatlon, such as task identifiers and trace capture 
stop/start infomiation, can also be placed In the trace cache 200. The precise contents and nature of the trace records 
are not considered critical to the Invention. 

[0062] Figure 6A Illustrates an exemplary format for reporting conditional branch events. In the disclosed embodiment 
of the invention, the outcome of up to 15 branch events can be grouped into a single trace entry! The 16-bit TDATA 
field {or "BFIELD") contains 1 -bit branch outcome trace entries, and is labeled as a TCODE = 0001 entry. The TDATA 
field Is Initially cleared except for the left most bit, which Is set to 1 . As each new conditional branch is encountered, a 
new one bit entry is added on the left and any other entries are shifted to the right by one bit. 
[0063] Using a 128 entry trace cache 200 allows 320 bytes of infomnation to be stored. Assuming a branch frequency 
of one branch every six instructions, the disclosed trace cache 200 therefore provides an effective trace record of 1 ,536 
instructions. This estimate does not take Into account the occurrence of call. Jump and return instmctions. 
[0064] In the disclosed embodiment of the Invention, the trace control logic 21 8 monitors Instruction execution via 
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processor interface logic 202. When a branch target address must be reported, information contained within a current 
conditional branch TDATA field is marked as complete by the trace control logic 218, even if 15 entries have not 
accumulated. As shovwi in Figure 6B. the target address (in a processor-based device 102 using 32-bit addressing) is 
then recorded In a trace entry pair, with the first entry (TCODE = 001 0) providing the high 1 6-bfts of the target address 
and the second entry (TCODE = 01 11 ) providing the low 1 e-bits of the target address. When a branch target address 
IS provided for a conditional jump instruction, no 1 -bit branch outcome trace entry appears for the reported branch 



STARTING AND STOPPING TRACE CAPTURE 



[0065] Referring now to Figure 6C. (t may be desirable to start and stop trace gathering during certain sections of 
program execution; for example, when a task context switch occurs. When trace capture is stopped, no trace entries 
are entered into the trace cache 200, nor do any appear on the bond-out pins of trace port 21 4. Different methods are 
contemplated for enabling and disabling trace capture. For example, an x86 command can be provided, or an existing 
x86 command can be utilized to toggle a bit in an I/O port location. Alternatively, on-chip breakpoint control registers 
(not shown) can be configured to indicate th^addr^sses^where trace capture should start/stop. When tracingis halted 
a trace entry fTCODE = 1000, TCODE = 0111) recording the last trace address Is placed in the trace stream Wheri 
tracing is resumed, a trace synchronization entry (TCODE = 0110. TCODE = 0111) containing the address of the 
currently executing instruction Is generated. 

[0066] It may be important to account for segment changes that occur while tracing is stopped. This situation can 
be partially resolved by selecting an option to immediately follow a TCODE = 1 000 entry with a current segment base 
address entry (TCODE = 0100. TCODE » 0111), as shown In Figure 6C. A configuration option is also desirable to 
enable a current segment base address entry at the end of a trace prior to entering Debug mode. By contrast it may 
not be desirable to provide segment base infonnation when the base has not changed, such as when an Interrupt has 
occurred. 

[0067] Referringto Figure 6D, following the occurrence of an asynchronous orsynchronous eventsuch as an interrupt 
or trap, a TCODE = 01 01 trace entry is generated to provide the address of the target interrupt handler. However it is 
also desirable to record the address of the instruction which was interrupted by generating a trace synchronization 
(TCODE = 0110) entry immediately prior to the Interrupt entry, as well as the previous segment base address (TCODE 
= 001 1 ). The trace synchronization entry contains the address of the last Instruction retired before the Interrupt handler 

commpnnPH 



commences 
SEGMENT CHANGES 



[0068] Rgure 6E Illustrates a trace entry used to report a change in segment parameters. When processing a trace 
stream in accordance with the invention, trace address values are combined with a segment base address to determine 
an instruction's linear address. The base address, as well as the default data operand size (32 or IS-bit mode) are 
subject to change. As a result, the TCODE = 001 1 and 01 1 1 entries are configured to provide the infomiation necessary 
to accurately reconstruct instruction flow The TDATA field corresponding to a TCODE = 001 1 entry contains the high 
1 6-bits of the previous segment base address, while the associated TCODE = 0111 entry contains the low 1 5 or 4 bits 
(depending on whether the instruction is executed in real or protected mode). The TCODE =0111 entry also preferably 
includes bits indicating the current segment size (32-bit or 16-blt), the operating mode (real or protected) and a bit 
indicating whetherpaging is being utilized. Segment Infomiatlon generally relates to the previous segment, not a current 
(target) segment. Cunrent segment information is obtained by stopping and examining the state of the processor core 
104. 

USER SPECIFIED TRACE ENTRY 

[0069] There are circumstance when an application program or operating system may wish to add additional Infor- 
mation into a trace stream. For this to occur, an x86 instruction Is preferably provided which enables a 1 6-bit data value 
to be placed in the trace stream at a desired execution position. The Instruction can be implemented as a move to 1/ 
0 space, with the operand being provided by memory or a register. When the processor core 104 executes this in- 
struction, the user specified trace entry Is captured by the trace control logic 21 8 and placed in the trace cache 200 
As shown In Figure 6F, a TCODE = 1001 entry Is used for this purpose In the disclosed embodiment of the Invention. 
This entry might provide, for example, a previous orcurenttaslc Identifier when a task switch occurs in a multi-taskina 
operating system. ^ 
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SYNCHRONIZATION OF TRACE DATA 

[0070] When executing typical software on a processor-based device 1 02 according to the disclosed embodiment 
of the Invention, few trace entries contain address values. IVIost entries are of the TCODE = 0001 format, in which a 
single bit indicates the result of a conditional operation. When examining a trace stream, however, data can only be 
studied in relation to a known program address. For example, starting with the oldest entry in the trace cache 200, all 
entries until an address entry are of little use. Algorithm synchronization typically begins from a trace entry providing 
a target address. 

[0071] If the trace cache 200 contains no entries providing an address, then trace analysis cannot occur. This situation 
is rare, but possible. For this reason, a synchronization register TSYNC is provided in the preferred embodiment of 
invention to control the injection of synchronizing address Information. If the synchronization register TSYNC is set to 
zero, then trace synchronization entries are not generated. 



6 0 

TSYNC (Trace Synchronization) 



Trace Entry Synchronization Entry Control Register. 

[0072] Figure 6G depicts an exemplary trace synchronization entry. In operation, a counter register Is set to the value 
contained in the synchronization register TSYNC whenever a trace entry containing a target address is generated. 
The counter is decremented by one for all other trace entries. If the counter reaches zero, a trace entry is Inserted 
(TCODE = 0110) containing the address of the most recently retired Instruction (or, alternatively, the pending instruc- 
tion). In addition, when a synchronizing entry is recorded In the trace cache 200, It also appears on the trace pins 220 
to ensure sufficient availability of synchronizing trace data for full-function ICE equipment. 
[0073] Trace entry information can also be expanded to include data relating to code coverage or execution perform- 
ance. This infomiatlon Is useful, for example, for code testing and perfomiance tuning. Even without these enhance- 
ments, It Is desirable to enable the processor core 1 04 to access the trace cache 200. In the case of a microcontroller 
device, this feature can be accomplished by mapping the trace cache 200 within a portion of 1/0 or memory space. A 
more general approach Invoh^es including an Instruction which supports moving trace cache 200 data into system 
memory. 

[0074] Thus, aprocessor-baseddevlceprovldingaflexible.hlgh-perfomiancesolutionforfumlshing Instruction trace 
Infonnation has been described. The processor-based device Incorporates an Instruction trace cache capable of pro- 
viding trace Infonnation for reconstructing Instruction execution flow on the processor without halting processor oper- 
ation. Both serial and parallel communication channels are provided for communicating trace data to external devices. 
The disclosed on-chip instruction trace cache alleviates various of the bandwidth and clock synchronization problems 
that arise In many existing solutions, and also allows less expensive external capture hardware to be utilized. 
[0075] The foregoing disclosure and description of the invention are illustrative and explanatory thereof, and various 
changes In the size, shape, materials, components, circuit elements, wiring connections and contacts, as well as In 
the details of the Illustrated circuitry and construction and method of operation may be made without departing from 
the spirit of the invention. 



Claims 

1. An electronic processor-based device (102) adapted to execute a series of Instructions obtained from external 
sources (1 06), the processor-based device being provided with pins to pemnit connection to extemai conductors, 
the electronic processor-based device being characterized by: 

a trace cache (200) coupled to a processor core (104) for storing trace Infonnation indicative of the order In 
which the instructions are executed by the processor core, the trace cache comprising a series of storage 
elements, each storage element being adapted to store trace infonnation, the trace information including a 
plurality of Instruction trace records containing address and data Infonnation, the trace cache (200) being 
configured to load data from the processor core (1 04) in response to a load command and configured for the 
processor core (104) to retrieve data from the trace cache (200) in response to a retrieve command; 
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and a communication channel connected between the trace cache (200) and selected ones of the pins to 
provide for transmission of trace Information from the trace cache to external devices. 

2. The processor-based device of clainfi 1 wherein the Instruction trace records each Include a trace data field (TDA- 
5 TA), and a trace code field (TCODE) for storing a code to Identify the type of data in the trace data field. 

3. The processor-based device of claim 1 or 2 configured to omit from stoi^d trace information Instruction trace 
records for instructions between instructions that disrupt the instruction flow. 

10 4. The processor-based device of claim 1 , 2 or 3 wherein information concerning executed branch Instructions having 
a target address that is not data register dependent Is stored in the trace cache in the form of a single bit. 

5. The processor-based device of any preceding claim, wherein the trace cache (200) is further configured to provide 
trace capture start/stop infomiatlon. 

15 

6. The processor-based device of any preceding claim, wherein the trace cache (200) is further configured to peri- 
odically capture a synchronizing entry, the synchronizing entry being the address of the Instruction most recently 
executed by the processor core (1 04). 

50 7. The processor-based device of any preceding claim, wherein the trace cache (20O) is further configured to provide 
intemipt or exception vector Infomiation. 

8. The processor-based device of any preceding claim, wherein each instruction trace record further includes a data 

valid bit (V). 

25 

9. The processor-based device of any preceding claim, wherein the trace cache (200) is further configured to provide 
task identifier infonnation. 

10. The processor-based device of any preceding claim, wherein the contents of the trace cache (200) are retrievable 
30 by an operating system 

11. The processor-based device of any preceding claim, wherein the communication interface comprises a serial In- 
terface (204) which is essentially compliant with the IEEE-1149.M990 JTAG Interface standard or other similar 
standard. 

35 

12. The processor-based device of any preceding claim, wherein the trace cache (200) is a first-ln. first-out (FIFO) 
circular cache. 

13. The processor-based device of any of claims 1 to 12, further comprising: 

40 

a processor interface (202) coupled to the processor core (1 04) and the trace cache, wherein the trace cache 
Is adapted to load the trace information from the processor core (104) via the processor interface (202), and 
wherein the processor core (104) is adapted to retrieve the trace Information from the trace cache via the 
processor interface (202). 

45 

14. A method for analysing trace information in a processor-based device (102) having a processor core (104), com- 
prising the steps of: 

providing a trace cache (200) within the processor-based device (102), the trace cache comprising a series 
so of storage elements adapted to store trace infomnation; 

capturing trace Infomiatlon from the processor core (1 04) that is Indicative of the order in which the series of 
instructions is executed by the processor core; 

storing the trace infonnation in the trace cache storage elements as instruction trace records; 
retrieving the trace infonnation by the processor core (1 04) from the trace cache storage elements in response 
55 to a retrieve command; and 

loading other information from the processor core (1 04) into the trace cache storage elements in response to 
a load command; 

providing a communication channel (230) from the trace cache to selected pins of the processor-based device 
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(102); and 

communicating the trace Infonnation from the trace cache (200) to the selected pins via the communication 
channel (230). 

15. The method of claim 14, wherein the loading and retrieving steps transfer the trace Information between the proc- 
essor core (104) and the trace cache via a processor Interface (202). 
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